HIPAA requires healthcare providers to protect patient data. Knowing which actions qualify as violations and breaches enables providers to reduce legal risks and safeguard patient data by identifying vulnerabilities and implementing suitable protective measures.
Enforcement has intensified. OCR reported a 264% increase in large breaches involving ransomware since 2018, and Paubox's 2026 Healthcare Email Security Report documented 170 email-related healthcare breaches in 2025 affecting more than 2.5 million individuals.
Definition and examples of HIPAA violations
A HIPAA violation is an event that causes non-compliance with the rules and regulations of HIPAA. This violates any one or more of the Security Rule requirements. These could include:
- Unauthorized access, such as sharing PHI with unauthorized persons
- Inadequate security measures, such as failure to monitor access to PHI
- Mishandling patient information, such as not providing secure encryption during the transit of data
One failure appears more than any other. The risk analysis requirement at 45 CFR 164.308(a)(1)(ii)(A) obliges organizations to identify where their ePHI sits and what threatens it, and OCR created a dedicated Risk Analysis Initiative because so few were doing it. By June 2026 the agency had completed 20 ransomware enforcement actions and 14 resolutions under that initiative. OCR Director Paula M. Stannard framed the agency's position in that announcement, stating that "effective cybersecurity starts with Security Rule compliance."
Read more: What is a HIPAA violation?
Consequences of HIPAA violations
HIPAA violation penalties vary based on the severity of the offense, categorized as civil or criminal penalties. Civil penalties are enforced by the US Department of Health and Human Services Office for Civil Rights, while criminal matters are referred to the Department of Justice under the HIPAA Enforcement Rule.
Civil penalties
These are divided into four tiers based on culpability. HHS applied its most recent inflation adjustment effective January 28, 2026, using an Office of Management and Budget multiplier of 1.02598 and raising every tier:
- Tier 1, no knowledge of the violation. $145 to $73,011 per violation
- Tier 2, reasonable cause, where the entity knew or should have known but did not act with willful neglect. $1,461 to $73,011 per violation
- Tier 3, willful neglect corrected within 30 days. $14,602 to $73,011 per violation
- Tier 4, willful neglect not corrected within 30 days. A minimum of $73,011 per violation
The statutory annual cap now sits at $2,190,294 for all violations of an identical provision in a calendar year. OCR applies lower caps to the first three tiers under a Notice of Enforcement Discretion published in the Federal Register in April 2019, which brings them to roughly $36,505 for Tier 1, $146,053 for Tier 2, and $365,052 for Tier 3, leaving only Tier 4 exposed to the full statutory amount.
Actual settlements land well below those ceilings. On April 23, 2026, OCR announced four ransomware settlements totaling $1,165,000 covering breaches that collectively affected more than 427,000 individuals, with individual amounts ranging from $225,000 to $375,000. Size does not determine exposure either. A settlement with MMG Fusion, a Maryland software company acting as a business associate, resolved a breach affecting roughly 15 million individuals for $10,000, while a settlement with OSF HealthCare over a Nephilim ransomware attack affecting 53,907 individuals came to $552,250. What drives the number is culpability and cooperation rather than headcount.
Nearly every settlement also carries a corrective action plan placing the organization under OCR monitoring, typically for two years.
Criminal penalties
Criminal violations are prosecuted by the Department of Justice and involve the intentional obtaining or disclosure of PHI. The penalties are set by statute at 42 U.S.C. 1320d-6 and are not adjusted for inflation the way civil penalties are.
Knowingly obtaining or disclosing PHI:
- Fine up to $50,000
- Imprisonment up to 1 year
Obtaining or disclosing PHI under false pretenses:
- Fine up to $100,000
- Imprisonment up to 5 years
Obtaining or disclosing PHI with intent to sell, transfer, or use for commercial advantage, personal gain, or malicious harm:
- Fine up to $250,000
- Imprisonment up to 10 years
Prosecutions remain uncommon next to civil enforcement, and the cases that reach court share a pattern. They involve employees who accessed and sold patient records for identity fraud, staff who viewed the files of celebrities or public figures with no treatment relationship, and insiders who passed PHI to outside parties for payment.
What constitutes a HIPAA breach
A breach is a distinct category of violation with a narrower definition. HHS defines it as the acquisition, access, use, or disclosure of PHI in a manner not permitted under the Privacy Rule that compromises the security or privacy of that information.
Under the Breach Notification Rule, covered entities and business associates are obligated to notify HHS and, in certain circumstances, the media when a breach occurs.
The presumption runs toward reporting. Unless a covered entity or business associate can demonstrate a low probability that the information was compromised based on a risk assessment, any such unauthorized use or disclosure is treated as a breach, which puts the burden on the organization to prove otherwise.
Performing a risk assessment
HHS specifies four factors that must be addressed when determining whether a breach has occurred:
- The nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification
- Who accessed or used the PHI
- Whether the PHI was actually acquired or viewed
- The extent to which the risk has been mitigated
The third factor has become harder to answer. When an attacker holds valid credentials or a stolen session token, their activity records in system logs as authorized use, which leaves organizations attempting to establish what was viewed using records that show nothing out of the ordinary.
Read more: What is a HIPAA risk assessment?
Consequences and notifications for breaches
HHS sets the notification requirements as follows. Affected patients must receive notice through first-class mail or email within 60 days of discovery. Breaches affecting 500 or more individuals in a state also require notice to prominent media outlets serving that state, and must be reported to the Secretary of HHS within 60 days. Breaches affecting fewer than 500 individuals are reported to HHS annually.
Reports involving 500 or more individuals are posted publicly on the OCR breach portal, naming the organization, the number of individuals affected, and the type of incident. That entry remains visible to patients, referring providers, and prospective partners long after the technical recovery is finished.
The difference between violations and breaches
Breaches carry more serious financial and criminal consequences than violations, and a violation can lead to a breach.
While any action in non-compliance with HIPAA can be considered a violation, a breach specifically involves the unauthorized access, use, or disclosure of PHI.
A HIPAA violation refers to any non-compliance with the rules and regulations set out by HIPAA. This could be due to not having the necessary safeguards to protect patient health information, not conducting a risk analysis, improper disposal of patient health records, unauthorized access to patient information, or sharing patient information without consent.
A HIPAA breach is a specific type of HIPAA violation. It occurs when there is unauthorized access, use, disclosure, or acquisition of PHI in a manner not permitted under the HIPAA Privacy Rule, which compromises the security or privacy of that information.
Examples of the difference between a HIPAA violation and a breach
- If a hacker breaks into a hospital's electronic health record system and steals patient data, that is a HIPAA breach. Similarly, if a hospital employee accidentally emails a document containing patient health information to the wrong person, that is also a HIPAA breach.
- A hospital employee accidentally leaves a patient's medical file unattended on a public transportation seat. Another passenger notices the file and realizes it contains sensitive medical information. Once that passenger opens the document, a breach has occurred.
- A nurse accidentally sends a patient's medical records to the wrong email address. This is a HIPAA violation because it involves the improper disclosure of PHI to an unauthorized recipient. Once the unauthorized recipient opens the document, it is considered a breach.
The April 2026 settlements show how the two connect in practice. In each of the four cases OCR resolved, the ransomware attack produced the breach, but the finding OCR cited was the failure to conduct an accurate and thorough risk analysis, a violation that existed before any attacker arrived. The violation came first. The breach followed from it.
Where email fits into the picture
A large share of reportable breaches begin in the inbox. Paubox's 2025 Healthcare Email Security Report found that employees report only 5% of known phishing attempts to their security teams, so the message that leads to a compromised account usually arrives unflagged.
Outbound email carries its own exposure, since a message sent to the wrong recipient becomes a reportable breach the moment it is opened. Paubox Email Suite encrypts every outbound message by default, with no keywords or manual steps required, which removes the judgment call about whether a given message needs protection. Paubox Inbound Email Security analyzes sender behavior, message intent, and contextual signals to catch phishing before staff encounter it.
Learn more: Paubox Email Suite | Paubox Inbound Email Security | HIPAA Compliant Email: The Definitive Guide
FAQs
Is every HIPAA violation also a breach?
No. A violation is any non-compliance with HIPAA rules, while a breach is the narrower category involving unauthorized access, use, or disclosure of PHI. Failing to conduct a risk analysis is a violation but not a breach on its own, though OCR has repeatedly found it to be the condition that allowed one.
How does OCR decide which penalty tier applies?
The tier depends on the organization's level of knowledge and whether it corrected the problem within 30 days. OCR also weighs the nature and extent of the violation, the number of individuals affected, and the entity's prior compliance history when setting an amount within that tier.
Do state regulators also enforce HIPAA?
Yes. State attorneys general have independent authority under the HITECH Act to bring actions on behalf of state residents, which means a single incident can produce an OCR settlement and a separate state penalty.
What triggers an OCR investigation?
Breach reports affecting 500 or more individuals are reviewed, and complaints can be filed by patients, employees, former employees, or business partners. Media coverage and referrals from other agencies also prompt investigations.
What is the most common finding in OCR enforcement actions?
An absent or inadequate risk analysis. OCR launched its Risk Analysis Initiative for that reason, and by mid-2026 the agency had completed 14 enforcement actions under it alongside 20 total ransomware resolutions.
